Cisco 400-251 Actual Free Exam Questions & Community Discussion

  • Exam Code/Number: 400-251
  • Exam Name/Title: CCIE Security Written Exam (v5.0)
  • Certification Provider: Cisco
  • Corresponding Certification: CCIE Security
  • Exam Questions: 125
  • Updated On: May 28, 2026
A sneaky employee using an Android phone on your network has disabled DHCP, enabled its firewall, and modified its HTTP user-agent header, to fool ISE into profiling it as a Windows 10 machine connected to the wireless network. This user can now get authorization for unrestricted network access using his Active Directory credentials because your policy states that a Windows device using AD credentials should be able to get full network access. However, an Android device should only get access to the web proxy. Which two steps can you take to avoid this sort of rogue behavior? (Choose two)
Correct Answer: C,F Vote an answer
How would you prevent making Cisco Email Security Appliance (ESA) an opened relay?
Correct Answer: C Vote an answer
Which of the following statement about Cisco Web Security Appliance is true?
Correct Answer: D Vote an answer
Which requirement for the FTD high availability setup is true?
Correct Answer: G Vote an answer
Which is true regarding Authentication Proxy?
Correct Answer: D Vote an answer
Policy Sets in ISE are used to
Correct Answer: C Vote an answer
0
0
0
10